AbsoluteJS

@absolutejs/agent-exchange-broker

@absolutejs/agent-exchange-brokerv0.3.0betaAI

Tenant-fenced, one-time token-confined broker contracts for AbsoluteJS Agent Exchange.

#Installation

BASH
bun add @absolutejs/agent-exchange-broker

#Capabilities

Overview

Executes one passkey-approved, purpose-bound Agent Exchange operation while confining an upstream bearer access token to deterministic provider code. The token is never returned to either agent, placed in the request, or serialized in the receipt.

This assurance is deliberately weaker than a DPoP or mTLS sender-constrained access token: compromise of the broker process can expose a live bearer token. Use tenant-isolated encrypted credential storage, an atomic durable store, restricted egress, short expiries, revocation, and aggressive rate limits.

The broker also accepts standing-mandate + token-confined-broker + purpose-bound after the host has cryptographically authorized and atomically consumed the request's separate mandateId. The broker does not verify mandates itself.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/agent-exchange-broker through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/agent-exchange-broker version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/agent-exchange-broker example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#Public entry points

Supported entry points declared by this package manifest.

@absolutejs/agent-exchange-brokerPackage entry point declared in package.json.

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts --outdir dist --target=node --external @absolutejs/agent-exchange && tsc --project tsconfig.build.json
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

9 symbols
TokenConfinedBrokerClaimtypePermalinkSource
TS
type TokenConfinedBrokerClaim = {
    readonly exchangeId: string;
    readonly expiresAt: number;
    readonly provider: string;
    readonly tenantId: string;
};
Exported from @absolutejs/agent-exchange-broker